Set up the AWS side so Sasha can use Claude models in your own AWS account
The steps in the AWS console that give you the Bedrock API key and region that the AWS Bedrock card in Settings → AI Admin needs, and the settings that stop Fable models failing.
- Where
- The AWS console (console.aws.amazon.com), Amazon Bedrock, first. Then Settings → AI Admin in Sasha.
- Who
- A Sasha admin, with an AWS account where you can create IAM users and use Amazon Bedrock.
- Needs
- An AWS account with billing set up, one of the regions that Sasha offers, a long-term Bedrock API key, and access to the Anthropic models. Fable models also need an AWS data-retention setting.
What this page is for
The AWS Bedrock (Private Cloud) card in Settings → AI Admin asks for an AWS Region and a Bedrock API Key. You make the key in your AWS account. This page tells you how, and which AWS settings the Claude models need. For the Sasha screen itself, see Choose where Sasha's AI runs, which model it uses, and how much it can read at once.
With Bedrock, AWS runs the models in your AWS account and sends the bill to you.
Step 1: choose the region
Sign in to the AWS console and choose the region at the top right of the page. It must be one that Sasha offers (see the questions above). Do all the next steps in that region.
Step 2: check the model access
- Open Amazon Bedrock.
- Open Playgrounds → Chat / Text, choose a Claude model, for example Claude Sonnet, and send a short message.
- If AWS shows a form about your use of Anthropic models, fill it in and send it. AWS asks for this once for each account. Access can take some minutes after you send it.
- If the message gets an answer, the account can use Claude models in this region.
Step 3: make a long-term API key
- In Amazon Bedrock, open API keys.
- Open the Long-term API keys tab and click Generate long-term API keys.
- Choose when the key expires. Write the date down.
- Click Generate.
- Copy the key now. AWS shows it only once. It starts with
ABSKQmVkcm.
AWS makes an IAM user for the key and gives it the policy AmazonBedrockLimitedAccess. Do not remove the policy: without it, Sasha cannot call the models.
Do not use a short-term key. It lasts at most 12 hours, and Sasha refuses it.
Step 4: Fable models
Skip this step if you will not use Fable 5 or Fable 5.1.
AWS allows Fable models only when the account's data-retention mode is aws_review in the region. In that mode, AWS keeps the prompts and answers of Fable models for up to 30 days for possible review by AWS. AWS does not share them with Anthropic. Opus, Sonnet and Haiku are not kept, whatever the mode.
The AWS console has no screen for this setting. A person with AWS credentials sets it with a signed request to https://bedrock.<region>.amazonaws.com/data-retention, with the body {"mode":"aws_review"}. See the AWS page Data retention in Amazon Bedrock. Allow about 5 minutes before you try a Fable model.
Make this choice with whoever is responsible for your data rules.
Step 5: connect in Sasha
- Open Settings → AI Admin and click Configure Bedrock →.
- Choose the same AWS Region and paste the Bedrock API Key.
- Click Get available models from Bedrock. Sasha sends a short test to each model and lists those your account can use.
- Choose a model under Select Model.
- In Configuration Notes, write the key's name and its expiry date.
- Click Save & Activate. The setting applies to every person in your Sasha.
Keep it safe
- Paste the key only into Sasha. Do not send it by email or chat.
- Sasha stores the key encrypted on your Sasha server. The screen never shows it again; it shows "Key on file".
- Give the key an expiry date, and put the date in your calendar.
- Use a key only for Sasha, so that you can delete it without stopping anything else.
- Set an AWS budget alert, because AWS bills each use of a model.
Questions
Which region do I choose?
Choose the region nearest to you or the one your data rules require. Sasha offers US East (N. Virginia), US East (Ohio), US West (Oregon), Europe (Ireland), Europe (London), Europe (Frankfurt), Asia Pacific (Singapore), Asia Pacific (Sydney) and Asia Pacific (Tokyo). Use the same region in AWS and in Sasha.
Does my data stay in my region?
Not always. Sasha calls the newer models through global inference profiles, so AWS can process a request in another AWS region. The data stays inside AWS and is not shared with Anthropic.
Sasha says "Invalid API key format". Why?
You pasted a short-term key, or a different kind of AWS key. Sasha accepts only a long-term Bedrock API key, which starts with ABSKQmVkcm. Short-term keys start with bedrock-api-key- and last at most 12 hours.
Get available models from Bedrock lists no models, or fewer than I expect. Why?
Your AWS account cannot use those models yet in that region. Open one Claude model in the Bedrock playground in the AWS console. If AWS asks for a use-case form for Anthropic models, send it and try again after some minutes. Also check that the key's IAM user still has its Bedrock policy.
Fable models fail with "data retention mode 'default' is not available for this model". Why?
AWS allows Fable 5 and 5.1 only when the account's data-retention mode is aws_review in that region. See "Fable models" below.
What happens when the key expires?
Chats fail with an error, and Sasha does not switch to another provider. Make a new key before the old one expires, paste it on the Bedrock card in Sasha and save. Write the expiry date in Configuration Notes on the card.
How do I stop Sasha's access?
In IAM, delete the Bedrock API key, or delete the IAM user that AWS made for it.